US2022217119A1PendingUtilityA1

Method for indicating a use of an illicit ip address

Assignee: SAGEMCOM BROADBAND SASPriority: Jan 7, 2021Filed: Jan 5, 2022Published: Jul 7, 2022
Est. expiryJan 7, 2041(~14.4 yrs left)· nominal 20-yr term from priority
H04L 61/5046H04L 2101/659H04L 45/72H04L 45/745H04L 63/0236H04L 63/1466H04L 63/126H04L 61/6059H04L 61/2046
34
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for indicating a use of an illicit IP address in a local communication network connected to a wide area communication network by a router, the method including: receiving a packet from at least one device in the local communication network using an illicit IP address; generating an error message marked with a predefined mark; sending the marked error message to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark.

Claims

exact text as granted — not AI-modified
1 . A method for indicating a use of an illicit IP address in a local communication network, the local communication network being connected to another communication network by means of a router, wherein the method comprises the steps, performed by the router, of:
 receiving a packet from at least one device belonging to the local communication network, said received packet comprising an illicit source IP address;   generating an error message packet and marking the error message packet with a predefined mark; and   returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark.   
     
     
         2 . The method according to  claim 1 , the method further comprising marking the packet received with the predefined mark and rejecting the packet received. 
     
     
         3 . The method according to  claim 1 , the method further comprising:
 recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address, in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as a first reception time, if the identifier is absent from the table of illicit IP addresses;   updating the table of illicit IP addresses if the identifier of the device is present in the table of illicit IP addresses.   
     
     
         4 . The method according to  claim 3 , wherein a first period being defined with a first predefined duration, the first period being counted as from the time of first reception, wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period if a time of disconnection of the device is not given in the table of illicit IP addresses. 
     
     
         5 . The method according to  claim 3 , wherein a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device, wherein a second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period, and wherein updating the table of illicit IP addresses comprises incrementing the received-packet counter for each packet received during the second period, if the time of disconnection of the device is given in the table of illicit IP addresses. 
     
     
         6 . The method according to  claim 4 , further comprising the step of deleting the identifier from the table of illicit IP addresses in the case where the first period has elapsed and the received-packet counter is equal to the initial value. 
     
     
         7 . The method according to  claim 4 , further comprising the step of forcing the device to reinitialise its network interface by disconnecting it from the local communication network, recording the time of disconnection in the table of illicit IP addresses and reinitialising the received-packet counter to the initial value, in the case where the first period has elapsed and the received-packet counter is different from the initial value. 
     
     
         8 . The method according to  claim 5 , further comprising: preventing, during a configured quarantine duration, any communication with the device when the first period has elapsed, if a time of disconnection of a network interface of the device is given in the table, and if the received-packet counter is different from the initial value. 
     
     
         9 . The method according to  claim 8 , wherein the configured quarantine duration increases at each new quarantine, a quarantine being a period during which any communication with the device prevented. 
     
     
         10 . The method according to  claim 9 , wherein the quarantine duration is equal to n*Dt where n is a number of quarantines and Dt is an initial quarantine duration. 
     
     
         11 . The method according to  claim 9 , wherein the quarantine duration is equal to 2 (n-1) *Dt where n is a number of quarantines and Dt is an initial quarantine duration. 
     
     
         12 . The method according to  claim 1 , wherein the first communication network and the other communication network use the IPv6 communication protocol. 
     
     
         13 . A router connecting a local communication network to another communication network, comprising:
 means for receiving a packet from at least one device belonging to the local communication network, the received packet comprising an illicit source IP address;   means for generating an error message packet and for marking the error message packet with a predefined mark; and   means for returning the marked error message packet to the at least one device using an additional routing table redirecting each packet to the local communication network and a routing rule applying the additional routing table to each packet marked with the predefined mark.   
     
     
         14 . A router according to  claim 13 , further comprising:
 means for recording in a table, referred to as an illicit IP address table, an identifier of the device using the illicit source IP address; in association with a received-packet counter initialised to an initial value, and in association with a time of reception of the received packet, referred to as the time of first reception, if the identifier is absent from the table of illicit IP addresses,   means for updating the table of illicit IP addresses, if the identifier of the device is present in the table of illicit IP addresses.   
     
     
         15 . The router according to  claim 14 , wherein the means for updating the table of illicit IP addresses comprise means for incrementing the received-packet counter for each packet received during a second period if a time of disconnection of the device is not given in the table of illicit IP addresses, a first period being defined with a first predefined duration, the first period being counted as from the time of first reception, the second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period. 
     
     
         16 . The router according to  claim 14 , wherein the means for updating the table of illicit IP addresses comprise means for incrementing the received-packet counter for each packet received during a second period, if the time of disconnection of the device is given in the table of illicit IP addresses, a first period being defined with a first predefined duration, the first period being counted as from a time of disconnection of said device, the second period being defined with a second predefined duration, the second predefined duration being shorter than the first predefined duration and terminating at the same time as the first period. 
     
     
         17 . The router according to  claim 15 , further comprising means for deleting the identifier from the table of illicit IP addresses in the case where the first period has elapsed and the received-packet counter is equal to the initial value. 
     
     
         18 . The router according to  claim 15 , further comprising means for forcing the device to reinitialise its network interface by disconnecting it from the local communication network, recording the time of disconnection in the table of illicit IP addresses and reinitialising the received-packet counter to the initial value, in the case where the first period has elapsed and the received-packet counter is different from the initial value. 
     
     
         19 . (canceled) 
     
     
         20 . An information storage medium, stores a computer program comprising instructions for implementing, by a processor, the method according to  claim 1 , when the program is executed by the processor.

Join the waitlist — get patent alerts

Track US2022217119A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.